CVE-2014-0171

Severity
5.0MEDIUM
EPSS
0.4%
top 40.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 13

Description

XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-gq3w-xqf6-838r: XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 62022-05-13
CVEList
CVE-2014-0171: XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 62015-01-15

📋Vendor Advisories

1
Red Hat
Odata4j: XML eXternal Entity (XXE) flaw2015-01-12

💬Community

1
Bugzilla
CVE-2014-0171 Odata4j: XML eXternal Entity (XXE) flaw2014-04-08